PT-2014-2032 · Yokogawa · Yokogawa Centum Cs 3000
Published
2014-03-14
·
Updated
2025-09-25
·
CVE-2014-0781
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Yokogawa CENTUM CS 3000 versions R3.09.50 and earlier
Description
The issue is related to a heap-based buffer overflow in the BKCLogSvr.exe service, which can be exploited by sending crafted UDP packets. This allows remote attackers to execute arbitrary code and potentially elevate their privileges. The vulnerability can be triggered by sending a specially crafted packet to port 52302/UDP.
Recommendations
For Yokogawa CENTUM CS 3000 versions R3.09.50 and earlier, consider restricting access to the BKCLogSvr.exe service and port 52302/UDP to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Buffer Overflow
Heap Based Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Yokogawa Centum Cs 3000